Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote attackers to cause a denial of service (crash) via a "text/html" HTML Content-type header sent in response to an XMLHttpRequest (AJAX).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.185
EPSS Ranking 95.0%